
CVE-2026-4025 The PrivateContent Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' shortcode attribute in the [pc-login-form] shortcode in all ve… https://www.cve.org/CVERecord?id=CVE-2026-4025
Post summary
The post announces that CVE‑2026‑4025 is a stored XSS flaw exploiting the 'align' attribute in the PrivateContent Free plugin’s [pc-login-form], with no evidence of PoC, exploit code, or active attacks.
